Privacy Policy
Last updated: June 2025 · Effective immediately
Zgrey ("we", "our", or "us") operates the Zgrey mobile application and website at zgrey.app (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information.
1. Information We Collect
- Account data: name, email address, country, and preferred currency when you register.
- Identity verification (KYC): government-issued ID documents and selfies submitted for KYC verification. Required by financial regulations.
- Financial data: wallet addresses, transaction history, trade records, deposit and withdrawal details.
- Payment methods: bank account names, account numbers, and mobile money details you add to facilitate P2P trades.
- Communications: messages exchanged with counterparties inside trade rooms, support tickets.
- Device data: IP address, device type, operating system, and app version for security and fraud prevention.
- Usage data: pages visited, features used, and interaction timestamps for app improvement.
2. How We Use Your Information
- To provide, operate, and maintain the Service.
- To verify your identity and comply with anti-money laundering (AML) and Know Your Customer (KYC) regulations.
- To process transactions, trades, and wallet operations.
- To send transactional emails (trade updates, deposit confirmations, security alerts).
- To detect, prevent, and investigate fraud, abuse, or illegal activity.
- To respond to support requests and resolve disputes.
- To improve our Service through analytics.
3. How We Share Your Information
- With trade counterparties: your first name, last name initial, and KYC status are visible to users you trade with.
- Service providers: hosting (DigitalOcean), email delivery, and analytics providers under data processing agreements.
- Legal obligations: when required by law, court order, or regulatory authority.
- We do not sell your personal data to third parties.
4. Data Retention
We retain account and transaction data for a minimum of 5 years to comply with financial regulations. You may request deletion of non-regulated data by contacting us.
5. Security
We use industry-standard encryption (TLS), hashed passwords (bcrypt), and JWT-based authentication. Two-factor authentication is available and encouraged. No method of transmission over the internet is 100% secure.
6. Your Rights
- Access, correct, or export your personal data.
- Request deletion of your account and non-regulated data.
- Opt out of marketing communications at any time.
- Lodge a complaint with your local data protection authority.
To exercise these rights, email us at [email protected].
7. Children's Privacy
The Service is not directed at children under 18. We do not knowingly collect data from minors.
8. Changes to This Policy
We may update this policy and will notify you by email or in-app notice. Continued use after changes constitutes acceptance.
9. Contact
Zgrey · [email protected] · zgrey.app